Through a parallel structure called the Witness field. And the protection of it via witness commit through OP_Return in the Coinbase transaction. And non-mining nodes verifying that new condition.
In simple words, SegWit is a manifestation of arbitrary data insertion.
Remember in Bitcoin everything is valid until invalidated explicitly.